https://bugs.openldap.org/show_bug.cgi?id=9343
--- Comment #5 from Ondřej Kuzník ondra@mistotebe.net --- OK, discussing other usecases, just having a URL to select policies by isn't going to do it: e.g. group membership can't be tested by a filter at this level.
Given that the range of options is too large, we might as well adopt a slapd.access(5)-like approach to configuration, with only filter= and group= being implemented for now.